[
https://issues.apache.org/jira/browse/CAMEL-25229?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Claus Ibsen resolved CAMEL-25229.
---------------------------------
Resolution: Fixed
Merged via https://github.com/apache/camel/pull/27255
> camel-hazelcast: serialization filter docs and WARN for user-supplied configs
> -----------------------------------------------------------------------------
>
> Key: CAMEL-25229
> URL: https://issues.apache.org/jira/browse/CAMEL-25229
> Project: Camel
> Issue Type: Improvement
> Components: camel-hazelcast
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.23.0
>
>
> Follow-up to CAMEL-23414.
> Camel applies a default {{JavaSerializationFilterConfig}} (allow-list
> {{java.}}, {{javax.}}, {{org.apache.camel.}}; deny-list {{java.net.}}) only
> to the Hazelcast configurations it builds itself. A configuration supplied by
> the user is used unchanged, by design:
> * a {{Config}} / {{ClientConfig}} bean passed as {{hazelcastConfig}}
> * a {{hazelcastConfigUri}}
> * a pre-built {{hazelcastInstance}}, or one looked up by
> {{hazelcastInstanceName}}
> The Java serialization settings of such an instance are whatever the user's
> configuration declares. Hazelcast's own default configurations
> ({{hazelcast-default.xml}}, {{hazelcast-client-default.xml}}) declare no
> {{<java-serialization-filter>}}, so a configuration based on them has no
> filter unless the user adds one.
> Today this is described only in the 4.18 and 4.21 upgrade guides. The
> camel-hazelcast component pages do not mention the serialization filter, and
> nothing at runtime tells users that the configuration they supplied has none.
> h3. Proposed changes
> # *Documentation*
> ({{components/camel-hazelcast/src/main/docs/hazelcast-summary.adoc}}): add a
> section explaining which instances get Camel's default filter (the ones Camel
> creates itself) and which do not (anything the user supplies). Show how to
> declare a {{JavaSerializationFilterConfig}} that covers the application's own
> classes, in XML and in Java, and mention the JVM-wide {{-Djdk.serialFilter}}
> alternative.
> # *Runtime WARN* ({{HazelcastDefaultComponent#getOrCreateHzInstance}} and
> {{#getOrCreateHzClientInstance}}): when Camel starts a member or client from
> a user-supplied {{Config}} / {{ClientConfig}} (bean or
> {{hazelcastConfigUri}}) whose {{SerializationConfig}} has no
> {{JavaSerializationFilterConfig}}, log a WARN pointing to the new
> documentation section. The user's configuration is not modified.
> # *Tests*: the WARN is logged for a user-supplied configuration without a
> filter, and is not logged when one is declared.
> h3. Out of scope
> Applying Camel's default filter to user-supplied configurations. Every
> application class outside the default allow-list would become unreadable, so
> that change would need its own discussion and an upgrade-guide entry.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)